CVE-2018-10731
Description
All Phoenix Contact managed FL SWITCH 3xxx, 4xxx, 48xx products running firmware version 1.0 to 1.33 are prone to buffer overflows when handling very large cookies (a different vulnerability than CVE-2018-10728).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Phoenix Contact FL SWITCH 3xxx/4xxx/48xx firmware 1.0-1.33 are prone to stack-based buffer overflow via crafted long cookie, leading to denial of service or arbitrary code execution.
Vulnerability
A stack-based buffer overflow exists in the web interface of Phoenix Contact FL SWITCH 3xxx, 4xxx, and 48xx series devices running firmware versions 1.0 to 1.33 [1]. The vulnerability is triggered when the device processes a specially crafted HTTP GET request containing a very large cookie value. This is distinct from CVE-2018-10728, which involves a different buffer overflow.
Exploitation
An unauthenticated remote attacker can exploit this vulnerability by sending a crafted HTTP GET request with an oversized cookie to the affected device [1]. No authentication or user interaction is required, and the attack can be carried out with low skill level.
Impact
Successful exploitation can result in a denial of service (device crash) or arbitrary code execution in the context of the web server [1]. This could allow an attacker to take full control of the switch, leading to potential network disruption or data compromise.
Mitigation
Phoenix Contact has released firmware updates to address this issue [1]. Users are advised to upgrade to firmware version 1.34 or later. If upgrading is not possible, the vendor recommends restricting network access to the web interface. No workarounds are provided. The vulnerability is not listed on CISA's Known Exploited Vulnerabilities (KEV) catalog.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1- Range: 1.0 - 1.33
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.securityfocus.com/bid/104231mitrevdb-entryx_refsource_BID
- cert.vde.com/de-de/advisories/vde-2018-007mitrex_refsource_CONFIRM
- ics-cert.us-cert.gov/advisories/ICSA-18-137-02mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.